CVE · Medium

CVE-2026-7798 — FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution [fluent-crm] < 3.0.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-7798 FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution [fluent-crm] < 3.0.0 Server-Side Request Forgery (SSRF) Medium 5.4 < 3.0.0 3.0.0 2026-05-21

CVE-2026-7798

The FluentCRM plugin for WordPress contains a security flaw affecting all versions up to 2.9.87, specifically in how it handles the 'SubscribeURL' parameter. This issue allows unauthorized users to initiate web requests from the application itself, potentially allowing them to access or modify internal data. The vulnerability can be exploited if the site has never been configured for SES bounce handling, as this would prevent the plugin's authentication check from functioning correctly.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.